Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,630
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,181 - 3,200 of 3,470 CVEs
CVE-2026-0610 CRITICAL - 9.8

SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

Published: Jan 19, 2026
Source: NVD
CVE-2026-1181 CRITICAL - 9.0

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could acce...

Published: Jan 19, 2026
Source: NVD
CVE-2025-10484 CRITICAL - 9.8

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is due to the plugin not properly verifying a users identity prior to authenticating them via the fma_lwp_set_session_ph...

Vendor: FmeAddons
Product: Registration & Login with Mobile Phone Number for WooCommerce
Published: Jan 17, 2026
Source: NVD
CVE-2025-15403 CRITICAL - 9.8

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' se...

Vendor: metagauss
Product: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Published: Jan 17, 2026
Source: NVD
CVE-2026-23800 CRITICAL - 10.0

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.

Product: Modular DS
Published: Jan 16, 2026
Source: NVD
CVE-2026-23744 CRITICAL - 9.8

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam insp...

Vendor: MCPJam
Product: inspector
Published: Jan 16, 2026
Source: NVD
CVE-2026-23722 CRITICAL - 9.1

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA system, specifically within the html/memorando/insere_despacho.php file. The application fails to properly sanitize or encode user-supplied input via t...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Jan 16, 2026
Source: NVD
CVE-2026-23523 CRITICAL - 9.6

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’...

Vendor: OpenAgentPlatform
Product: Dive
Published: Jan 16, 2026
Source: NVD
CVE-2025-14894 CRITICAL - 9.8

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process ...

Vendor: livewire-filemanager
Product: filemanager
Published: Jan 16, 2026
Source: NVD
CVE-2025-59870 CRITICAL - 9.8

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

Vendor: hcltech
Product: myxalytics
Published: Jan 16, 2026
Source: NVD
CVE-2025-60021 CRITICAL - 9.8

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided extra_options parame...

Vendor: apache
Product: brpc
Published: Jan 16, 2026
Source: NVD
CVE-2026-0975 CRITICAL - 9.8

Delta Electronics DIAView has Command Injection vulnerability.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2026-1021 CRITICAL - 9.8

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: gotac
Product: police_statistics_database_system
Published: Jan 16, 2026
Source: NVD
CVE-2026-1019 CRITICAL - 9.8

Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

Vendor: gotac
Product: police_statistics_database_system
Published: Jan 16, 2026
Source: NVD
CVE-2025-62582 CRITICAL - 9.8

Delta Electronics DIAView has multiple vulnerabilities.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2025-62581 CRITICAL - 9.8

Delta Electronics DIAView has multiple vulnerabilities.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2025-61937 CRITICAL - 10.0

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the  model application server.

Vendor: aveva
Product: process_optimization
Published: Jan 16, 2026
Source: NVD
CVE-2025-14237 CRITICAL - 9.8

Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 ...

Published: Jan 16, 2026
Source: NVD
CVE-2025-14236 CRITICAL - 9.8

Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and ear...

Published: Jan 16, 2026
Source: NVD
CVE-2025-14235 CRITICAL - 9.8

Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06...

Published: Jan 16, 2026
Source: NVD